Android adds secure bridge for moving digital credentials

Switching password managers on Android no longer requires risky manual exports, thanks to a new system-level transfer protocol.
Android users can now move their passwords and passkeys between different security apps without exposing their data to the open web. This update eliminates the long-standing practice of downloading sensitive credentials into unprotected text files, a method that left users vulnerable to interception on their own devices. By handling the migration at the operating system level, the new feature aims to make switching providers as safe as it is to use them.
Previously, moving digital keys required users to manually recreate them across numerous sites and apps, a tedious and error-prone process. The new system-level approach automates this coordination, allowing the phone to mediate the secure exchange between applications. According to reporting from 9to5Google, this change marks a significant shift in how Android handles sensitive user data during account transitions.
How the secure transfer mechanism works
The process begins when a user opens their new password manager and selects the option to import credentials from a previous provider. The application then hands the task over to the Android operating system, which automatically detects other credential managers installed on the device. This detection phase ensures that the user is shown only valid sources for the transfer, reducing the risk of misdirecting sensitive data.
After selecting the source, the user must review and authorize the action within the old application. Once approved, the data is transferred directly between the two apps in a matter of seconds. This direct hand-off bypasses intermediate storage, meaning the credentials never sit exposed in a plain-text file on the phone’s storage, significantly lowering the attack surface for malware or unauthorized access.
Supported applications and future participation
At launch, this secure transfer capability is supported by Google Password Manager, 1Password, Bitwarden, and Dashlane. These major providers have integrated with the Credential Manager’s Credentials Transfer API to enable the feature. Users attempting to switch between any of these four services will experience the streamlined, system-mediated process described above.
Other developers can join this ecosystem by implementing the same API, allowing them to offer the same secure import and export functions. However, there is a clear trade-off: if a user’s current or target password manager does not support this specific standard, the secure system-level transfer will not be available. In those cases, users are still forced to rely on older, less secure manual methods or third-party workarounds to move their digital keys.
Implications for user security habits
This update simplifies a task that many users avoided due to the complexity and risk involved. By making the transfer process native to the OS, Android reduces the cognitive load on users who need to switch providers for privacy or feature reasons. The primary benefit is that the most sensitive part of the migration is now handled by the trusted operating system rather than the user’s potentially flawed manual procedures.
Nevertheless, users should remain cautious about which apps they authorize for this process. While the system provides a secure channel, the initial decision to share credentials with a new app remains a critical trust point. The ease of transfer means that mistakes in selecting the wrong destination or authorizing a malicious application could have immediate and severe consequences, making vigilance just as important as the technical security improvements.






